Headline
GHSA-jj46-9cgh-qmfx: Mattermost Improper Access Control vulnerability
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2023-47865
Mattermost Improper Access Control vulnerability
Moderate severity GitHub Reviewed Published Nov 27, 2023 to the GitHub Advisory Database • Updated Nov 28, 2023
Package
gomod github.com/mattermost/mattermost-server/v6 (Go)
Affected versions
< 7.8.13
gomod github.com/mattermost/mattermost/server/v8 (Go)
Published to the GitHub Advisory Database
Nov 27, 2023
Last updated
Nov 28, 2023